EU Gains Power to Fine, Block and Inspect AI Models, and OpenAI, Anthropic Are in the Crosshairs
New enforcement rules that took effect this week let European regulators demand access to AI systems before they go on sale in Europe, and hit companies with fines of up to 15 million euros for non-compliance.

Key points
- The EU's new enforcement powers over general-purpose AI models, meaning AI systems that can do many tasks at once like the technology behind ChatGPT and Claude, took effect on Sunday.
- Regulators can fine a company up to 15 million euros or 3% of its annual global revenue, whichever figure is larger.
- Any company selling an AI model inside the EU must comply, regardless of where it is headquartered.
- OpenAI confirmed it is in contact with the EU AI Office; Anthropic had previously resisted sharing access to its Mythos model for months.
- The EU is separately in talks with both companies following reports that their models were involved in recent cyber attacks.
Europe's AI watchdog just got teeth.
As of Sunday, the European Commission, the executive body that proposes and enforces EU law, can demand to inspect an AI model before it goes on sale in Europe, block it from the market entirely, or fine its maker up to 15 million euros or 3% of global annual revenue, whichever sum is higher. The target is any company offering a general-purpose AI model, the kind of flexible, broad-capability system that powers products like ChatGPT or Claude, to anyone inside the EU.
That scope matters. A company does not need a European office to fall under these rules. As Elisabetta Righini, a partner at law firm Sidley Austin, told CNBC Tech: "A U.S. address does not put a lab outside the EU regulator's reach." Non-EU providers must also appoint an EU-based legal representative to act as a point of contact for regulators.
What can regulators actually do?
They can demand information, run their own model evaluations, and fine companies even for procedural slip-ups. Refusing an information request, giving misleading answers, or blocking an inspection each count as separate violations, Righini said, meaning fines can stack up before a regulator ever rules on the AI system's actual behaviour.
The new powers are part of the phased rollout of the EU AI Act, a sweeping law passed in 2024 that sorts AI systems by risk level and sets different rules for each tier. These latest powers cover the most capable, general-use models at the top of that ladder.
Why does this matter for ordinary people?
If regulators block or restrict a popular AI tool in Europe, users there may find features disappear or services become unavailable. Prices could also shift if companies face large fines and pass costs on.
The companies most exposed right now are the biggest American AI labs. Anthropic took months before agreeing to share access to its Mythos model with EU officials. The EU is also in talks with both Anthropic and OpenAI following reports of their models being used in cyber attacks. OpenAI confirmed contact with the EU AI Office. Tom Gordon, OpenAI's VP for European policy, said the company has "collaborated closely with the European Commission" and will continue doing so.
| Company | Status | Public statement |
|---|---|---|
| OpenAI | Confirmed talks with EU AI Office | Committed to working with Commission |
| Anthropic | Shared Mythos model access after months of delay | No comment by publication time |
| Previously fined $1 billion by EU in July 2025 | Pledged to meet all applicable rules |
Google's July fine came after European regulators found the company favoured its own services over rivals. U.S. President Donald Trump responded by threatening the EU with new tariffs, a sign of how quickly AI regulation can spill into broader trade disputes.
What happens next?
The Commission has enforcement power now, but how aggressively it uses it will become clear over the coming months. Companies that sell AI tools in Europe should expect requests for documentation and, potentially, pre-release evaluations of new models. Regulators have signalled they view the most advanced systems as posing risks "on an entirely new scale," in the words of Henna Virkkunen, the Commission's executive vice-president for tech sovereignty.
For now, the rules are in place. The fines are real. And the reach extends to any lab whose model a European user can open on a browser.



